Monitoring Splunk

Edit All Matching Notable Events - Can we undo this?

DanAlexander
Communicator

Hello folks!

That is my first post here and I hope you guys help me with my issue.

I have inadvertently selected 4000+ notes and closed them all with the same note. 

Is there any script or anything on the ES Splunk UI I miss that can undo my mistake?

Your help is much appreciated!

Thank you all. 

0 Karma

tah7004
Path Finder

This might be a bit late but I actually did the same and would like to offer solution for others in same situation. 

You just need to delete the entries from the incident_review lookup which should be a kv store. 

I would test first to ensure that you don't accidentally delete your other legitimate updates because they can easily be wiped out.

I used the lookup editor to do this.  I would carefully test out first before trying any bulk deletes though.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...